Overview

At a high-level, this service replicates your resources in a failover site to help you:

Troubleshoot during an outage in your primary data center

Meet compliance requirements

This service replicates the following resources from your production environment into the failover site:

Resource type

Specific components

Infrastructure

Workloads

Virtual machines

Networking

IP addresses

L2L VPN

SSL/VPN

Security

Malware protection

File Integrity Monitoring

Patching

Log Management

If there is an outage in your primary data center, and you continue to work with your infrastructure in the failover site, then any modifications you make will be not replicated in the primary data center once the outage has been resolved.

Typically, the failover site is the closest data center to your primary data center. Currently, Armor offers this service in the following locations:

Primary data center

Default failover site

Dallas (DFW01)

Phoenix (PHX01)

Phoenix (PHX01)

Dallas (DFW01)

Prerequisites

Before your order this add-on product, consider the following scenarios:

In Gen 3 (my.armor.com), you were able to access your virtual machine via the Cisco AnyConnect Secure Mobility Client. In Gen 4 (amp.armor.com), you can only access virtual machines via the VMwareTRAY SSL VPN-Plus Client. Even after you upgrade to Gen 4, you can still use the Cisco to access your transferred virtual; machines; however, for a virtual machine that is replicated to the failover site, you can only access that virtual machine via the VMware client. In short, Armor recommends that you use the VMware client to access your virtual machines.

Even during a data center outage, you must submit a support ticket to Armor to request a live failover.

Any changes you make in your virtual machine while in the replication site will not be transferred over to the primary site at the end of the failover.

Based on the size of your environment, first-time provisioning for this add-on product can take up to two days to complete.

Based on the size of your environment, a failover may take

Order Continuous Server Replication (Disaster Recovery)

If your Gen 3 virtual machines were subscribed to Continuous Server Replication (Disaster Recovery), then as part of the upgrade process, Armor has automatically subscribed those virtual machines to Continuous Server Replication (Disaster Recovery) in Gen 4. In this case, you do not need to order Continuous Server Replication (Disaster Recovery). However, for any Gen 3 virtual machine that did not have Continuous Server Replication (Disaster Recovery), or for new Gen 4 virtual machines, you must order Continuous Server Replication (Disaster Recovery).

You can order Continuous Server Replication (Disaster Recovery) from the Virtual Machine Details screen in the Armor Management Portal (AMP).

In the Armor Management Portal (AMP), on the left-side navigation, click Infrastructure.

Click Virtual Machines.

Locate and select the desired virtual machine.

Next to the virtual machine name, click the gear icon.

Select Add Continuous Replication.

In the drop-down menu, confirm the desired virtual machine.

Review the information, including pricing information, and then select Submit.

For first-time users, it may take up to two business days for this add-on product to be fully provisioned in your account. After this first-time provisioning process, additional provisioning will only take 30 minutes to complete.

To confirm that this service was activated:

Return to the Virtual Machine Details screen for the desired virtual machine.

Click the Continuous Server Replication tab.

Review the status for Server Replication.

(Optional) Armor recommends that after your add-on product has been fully provisioned, you should request a test failover, simply to verify the service.

Request and view a test failover

You can request a test failover to meet compliance requirements or to verify that the add-on product was successfully provisioned.

After a successful test failover, you can view and confirm the test failover in the Armor Management Portal (AMP).

During a test failover, Armor recommends that you do not make any changes to your virtual machine in the failover site. Any change you make will not replicated in the primary site.

In the Armor Management Portal (AMP), on the left-side navigation, click Support.

Click Tickets + Notifications.

Click New Ticket.

In Ticket Subject, enter Request for a Test Failover.

(Optional) In Add Recipient, enter the name or username of additional recipients to add to the ticket, and then select the name.

In Ticket Explanation, enter the name of the corresponding virtual machine.

Click Create Ticket.

To view the status of your ticket, in the left-side navigation, click Support, and then click Tickets + Notifications.

Armor Support will update the ticket when the test failover is complete.

On the left-side navigation, click Infrastructure.

Click Virtual Machines.

The failover will be listed in the table. The name of this virtual machine will include the name of the original virtual machine, along with Test added to the title.

For example, if the name of the virtual machine is My Company, then the failover virtual machine will appear as My Company - Test.

Click the Test virtual machine.

Next to Region, the data center will list the secondary data center (the location for the disaster recovery for your virtual machine).

Under Storage, the disk is tagged with Disaster Recovery.

The Continuous Server Replication tab will not appear in the failover virtual machine.

(Optional) To access the virtual machine in the failover site, you must download and install the Gen 4 SSL/VPN client for the failover site.

You cannot use the Gen 3 (Cisco AnyConnect) client to connect to the virtual machine in the failover site; you must use the Gen 4 (VMware) client.

You must have the Read Server Replication and Write Server Replication permissions enabled. Contact your account administrator to enable this permission. To learn how to update you permissions, see Roles and Permissions (Armor Complete).

Frequently asked questions

I had Continuous Server Replication (Disaster Recovery) in my Gen 3 (my.armor.com) environment. Do I need to order this add-on product again in my Gen 4 (amp.armor.com) environment?

For any Gen 3 virtual machine that did not have Continuous Server Replication (Disaster Recovery), or for newly created Gen 4 virtual machines, you must order Continuous Server Replication (Disaster Recovery) in AMP.

How do I order Continuous Server Replication (Disaster Recovery) and request a failover?

In short, you can order the Continuous Server Replication (Disaster Recovery) add-on product in the Armor Management Portal (AMP). Once this add-on product has been fully provisioned, you can submit a support ticket to request a failover. Armor Support will coordinate with you to establish expectations and timelines.

If my primary data center is down, does Armor automatically perform a failover?

Although Armor will notify you about a data center outage, you are still responsible for communicating a failover request to Armor.

Similarly, although Armor will notify you about the end of a data center outage, you must contact Armor to terminate the failover.

If I make a change while working in the failover site, will that change be reflected in the primary site?

In short, no. After a failover is complete, Armor removes the failover virtual machine from the Armor Management Portal (AMP). As a result, any change you make to your failover virtual machine will not reflected in the primary virtual machine.

How do I terminate a failover?

You must submit a request to Armor Support and indicate your interested to terminte the failover.

How does Continuous Server Replication (Disaster Recovery) affect how information is displayed in AMP?

Each virtual machine that is created contains a unique agent ID. During a failover, your virtual machine is essentially recreated in the failover site, which means this virtual machine will contain a new agent ID. After a failover, your virtual machine is recreated (again) in the primary site, with a new agent ID. As a result of these different agent IDs, there may be some discrepancies between the information that is displayed in AMP.

For example, in the Log Management screen, you noticed multiple entries for the same virtual machine under the VM column. Although log collection is taking place and the friendly name of the virtual machine is the same, the collected logs are corresponding to different agent IDs, hence the additional of multiple entries for the same virtual machine.

How do I access a failover virtual machine?

Similar to accessing a primary virtual machine, you must download and install an SSL/VPN client that corresponds to the failover site.

To access a failover virtual machine, you cannot use the Gen 3 (my.armor.com) SSL/VPN client. You can only use the Gen 4 (amp.armor.com) SSL/VPN client.

To learn how to download and install an SSL/VPN client in Gen 4, see SSL/VPN.

What aspects of my environment are replicated into the failover site?

How long does it take my for environment to be replicated in the failover site?